In Healthcare, the Systems That Support Care Are Now Part of Care

In Healthcare, the Systems That Support Care Are Now Part of Care

Images
Authored by
Josh Leclerc
Date Released
18 August, 2026
Comments
No Comments

The NKST Healthcare Security & Risk Summit 2026 did not treat cybersecurity as a technology problem. It treated it as a continuity problem. That distinction is where the conversation needs to live.

Healthcare cybersecurity programs have spent years trying to justify themselves in board presentations and budget cycles. The NKST Healthcare Security & Risk Summit 2026, co-hosted by Sunnybrook Health Sciences Centre in Toronto, offered a different frame. The summit theme was Uninterrupted Care: Engineering Resilience for the Next Surge. That framing matters because it stops treating security as a discipline adjacent to clinical operations and places it where it actually belongs.

The message across the day was clear. Cyber resilience is not just about stopping attacks. It is about protecting the organization’s ability to keep operating when an attack is already underway. Those are related goals, but they are not the same goal. Organizations that conflate them tend to invest heavily in prevention while leaving their recovery assumptions untested.

Healthcare has a different risk profile than almost every other sector

A bank can close a branch. A retailer can delay an order. A manufacturer can pause a line. A hospital does not get those options.

Clinical operations depend on identity systems, EHR platforms, medical devices, network connectivity, pharmacy access, imaging systems, nurse call workflows, and vendor integrations that rarely appear on a board slide until they fail. That dependency stack is deep, interconnected, and largely invisible to the people who set security budgets.

The systems that support care are now part of care. When those systems are disrupted, the impact is not abstract. It is operational, clinical, reputational, legal, and human. The point is not that every cyber incident immediately becomes a patient safety event. The point is that healthcare leaders no longer have the luxury of assuming it will not.

What disruption looks like in practice

When a hospital network experiences a ransomware event, the visible consequence is rarely just data loss. It is staff reverting to paper processes under clinical pressure. Delayed medication administration. Imaging workflows that stop. Care transfers to other facilities. Emergency departments managing surge with degraded tooling. The cyber event becomes a care delivery event within hours, sometimes minutes.

That is the risk profile healthcare security programs are being asked to address. Not only breach containment. Continuity of care under digital disruption, with clinical consequences attached to every hour of delay.

Identity is a care continuity control, not just an IT control

Healthcare runs on access. Clinicians, nurses, residents, contractors, researchers, students, administrators, vendors, and shared clinical workflows all create identity realities that few other sectors face at the same scale or urgency.

The challenge is not simply whether access is secure. The challenge is whether access is accurate, timely, governed, and resilient under pressure. Can a clinician still reach the system they need during a disruption? Can access be removed quickly when a role changes or a contract ends? Can privileged access be isolated when compromise is suspected? Can third-party vendor sessions be monitored without creating friction for legitimate clinical work? Can workforce changes flow cleanly into EHR platforms without creating orphaned accounts?

These are not administrative questions. They are operational resilience questions. An identity program that cannot answer them is not just a security gap. It is a continuity gap. In healthcare, the two are the same thing.

Ontario’s PHIPA and federal PIPEDA both require health information custodians to implement reasonable safeguards over personal health information, including controls governing who can access it and under what conditions. Access governance is not only a security program deliverable. It is a statutory obligation with legal consequence when it fails during an incident.

AI is being adopted faster than governance can follow

Artificial intelligence was one of the dominant topics of the summit. That is not surprising. Healthcare organizations are going to adopt AI because the pressure to do so is real. Clinical scribes, analytics, diagnostics, operational automation, and security assistance all have genuine potential to reduce burden and improve decisions under pressure.

The risk is not that healthcare uses AI. The risk is that governance cannot move at the pace of deployment. An AI tool handling personal health information is not only an innovation project. It is a privacy, security, vendor, and clinical risk decision that requires the same discipline applied to any other system with access to sensitive data.

The governance gap is a security gap

AI deployed without data classification creates new privacy exposures. AI deployed without vendor assessment creates new third-party dependencies with unclear security obligations. AI deployed without access controls and logging creates accountability gaps that are difficult to close after the fact. And AI deployed without a clear picture of adversarial use creates blind spots at exactly the moments that matter most.

Adversaries are adopting the same capabilities. More convincing phishing at scale. Voice cloning for executive impersonation. Synthetic clinical content designed to manipulate staff making fast decisions under pressure. The control model has to account for both sides: using AI responsibly and defending against attackers who use it well.

The human layer in healthcare looks different than in most environments

Security awareness programs in most sectors still treat the user as the weakest link to be hardened through repetition. In healthcare, that framing misses the operating reality. Clinicians, nurses, and support staff are making dozens of high-consequence decisions across a shift under time pressure, in shared physical environments, often using shared workstations and transitioning between systems rapidly. Security is not their primary job. It cannot be.

The more useful frame is designing controls that work in the environment as it actually operates. Shift changes. Remote access during on-call. After-hours escalation with thin teams. Clinical urgency that cannot wait for a help desk ticket. A control that looks sound in a policy document can fail completely in a hallway at 2:00 a.m. during a patient surge.

Voice cloning, executive impersonation, patient-themed lures, and AI-generated urgency all increase the convincingness of attacks without increasing the technical sophistication required to run them. The answer cannot be telling healthcare workers to be more careful. The answer is better verification paths, clearer escalation habits, and better system design that reduces the pressure placed on individual judgment at the wrong moment.

Resilience has to be engineered before the incident

Resilience is not a posture that organizations arrive at through policy and good intentions. It has to be designed, tested, measured, and improved before the incident arrives. That is what the summit theme meant by engineering. Segmentation that reflects clinical reality, not legacy infrastructure decisions. Backups where recoverability is actually tested, not just assumed from a completed job log. Emergency access that is controlled without becoming a permanent exception. Downtime procedures that clinical staff have practiced, not documents stored in a folder no one has opened since they were written.

Incident response plans need to include clinical leadership, privacy counsel, legal, communications, vendor contacts, and executives from the first hour, not as an afterthought after the technical team has exhausted its options. Tabletop exercises should force real decisions: which care functions take priority, who can authorize isolating a clinical system, when does the incident become a command-centre event, how are patients and staff informed, and what happens when the primary communication platform is unavailable.

Medical device risk deserves specific attention. The clinical environment carries legacy technology under active operational constraints. Devices that cannot be patched quickly, cannot run endpoint agents, and cannot be taken offline without clinical consequences are not edge cases. They are a structural feature of most hospital networks. The control strategy has to account for that reality rather than assume it away.

Prevention still matters. Detection still matters. But resilience asks the harder question: what must continue working when prevention has already failed?

What the day reinforced

Healthcare cybersecurity is becoming more executive, more operational, more clinical, and more connected to resilience planning. Ransomware, email security, endpoint protection, and vulnerability management still matter. They now sit inside a larger question: can the organization continue to deliver safe care under digital pressure?

For lean IT and security teams, start with operational clarity. Which systems would create a genuinely dangerous situation if they failed during peak clinical hours? That list drives resilience priority. Not because everything else is unimportant, but because those systems define the floor of what must survive disruption.

For larger environments, the conversation has moved to the executive level. Cyber resilience is a governance question, not only a security program question. Boards need to understand the clinical and reputational consequence of prolonged system disruption, and that understanding has to come from tested assumptions, not from a threat briefing read in advance of an incident.

The next surge may be a volume surge. It may be an AI-enabled social engineering campaign, a vendor outage, a cloud disruption, an identity compromise, or a medical device constraint. It may be several of those at once. The organizations best positioned will not be the ones with the longest list of tools. They will be the ones that understand their critical workflows, know their dependencies, test their assumptions, and have built their security programs around the one outcome that cannot be compromised in healthcare.

Uninterrupted care.

Sources and further reading

How Arancia Can Help

Cyber resilience in healthcare is an engineering problem, not a policy problem.

Arancia helps healthcare organizations build security programs that reflect clinical operational reality, connecting identity governance, resilience planning, vendor risk, and incident response to the continuity of care as the primary outcome.

  • Healthcare identity governance assessment, including EHR access review and privileged access controls
  • Cyber resilience program design aligned with clinical continuity requirements
  • Downtime procedure review and tabletop exercises designed for clinical environments
  • Medical device and OT risk assessment with compensating control frameworks
  • AI security, privacy, and vendor governance assessments for healthcare deployments
  • Incident response planning that integrates clinical leadership, legal, and communications from the first hour

Arancia works with healthcare organizations that need security programs built around the operational reality of delivering care. Get in touch.

Subscribe to our monthly security bulletin

By submitting this form, you acknowledge that your personal data will be processed in accordance with Arancia Privacy Policy and Terms of Use.